CVE-2024-10237

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Feb 4, 2025
CWE ID 347
CWE ID 345

Summary

CVE-2024-10237 reveals a vulnerability in the firmware image authentication design of the Supermicro MBD-X12DPG-OA6 motherboard. Malicious actors can exploit this weakness to manipulate the firmware undetected, bypassing BMC inspection and the signature verification process. This could potentially enable unauthorized access and compromise system security. Supermicro urges users to update their firmware as soon as a patch becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share